nerdexam
Check_Point

156-215.80 · Question #205

You installed Security Management Server on a computer using GAiA in the MegaCorp home office. You use IP address 10.1.1.1. You also installed the Security Gateway on a second GAiA computer, which…

The correct answer is B. 2, 1, 3, 4, 5. This question tests the correct procedural order for establishing SIC between a Security Management Server and a Gateway that will be shipped to a remote site.

Deployment and Configuration

Question

You installed Security Management Server on a computer using GAiA in the MegaCorp home office. You use IP address 10.1.1.1. You also installed the Security Gateway on a second GAiA computer, which you plan to ship to another Administrator at a MegaCorp hub office. What is the correct order for pushing SIC certificates to the Gateway before shipping it? 1. Run cpconfig on the Gateway, select Secure Internal Communication, enter the activation key, and reconfirm. 2. Initialize Internal Certificate Authority (ICA) on the Security Management Server. 3. Configure the Gateway object with the host name and IP addresses for the remote site. 4. Click the Communication button in the Gateway object's General screen, enter the activation key, and click Initialize and OK. 5. Install the Security Policy.

Options

  • A2, 3, 4, 1, 5
  • B2, 1, 3, 4, 5
  • C1, 3, 2, 4, 5
  • D2, 3, 4, 5, 1

How the community answered

(41 responses)
  • A
    7% (3)
  • B
    73% (30)
  • C
    15% (6)
  • D
    5% (2)

Why each option

This question tests the correct procedural order for establishing SIC between a Security Management Server and a Gateway that will be shipped to a remote site.

A2, 3, 4, 1, 5

Order 2,3,4,1,5 attempts to push SIC via the Communication button (step 4) before the activation key has been configured on the gateway itself (step 1), so the key exchange would fail.

B2, 1, 3, 4, 5Correct

The ICA must be initialized on the SMS first (step 2) so it can issue certificates. While the gateway is still physically accessible, cpconfig is run locally to set the activation key (step 1). Once shipped, the gateway object is configured in SmartDashboard (step 3), the Communication button is used to push the SIC cert using the matching activation key (step 4), and finally the Security Policy is installed (step 5).

C1, 3, 2, 4, 5

Order 1,3,2,4,5 attempts to initialize SIC on the gateway (step 1) before the ICA even exists on the SMS (step 2), making certificate issuance impossible.

D2, 3, 4, 5, 1

Order 2,3,4,5,1 attempts to install the Security Policy (step 5) before the activation key is set on the gateway (step 1), meaning SIC has not been fully established and policy push would fail.

Concept tested: Check Point SIC initialization order for remote deployment

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_SecurityManagement_AdminGuide/html_frameset.htm

Topics

#SIC#certificate push#deployment order#Security Management Server

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice